<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — KNX Association</title><description>Actively exploited vulnerabilities affecting KNX Association products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/knx-association.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2023-4346 — KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability</title><link>https://wildfortech.com/security#CVE-2023-4346</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2023-4346</guid><description>The KNX building automation protocol&apos;s Connection Authorization Option 1 contains a flaw in its account lockout mechanism. An attacker can exploit this to wipe all devices on a KNX installation and set a BCU key that effectively locks administrators out of their own devices — provided no additional security options are enabled. This is particularly serious in building control environments where KNX manages lighting, HVAC, access control, and other physical systems, meaning a successful attack could cause sustained operational disruption.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>KNX Association</category><category>KNX Protocol Connection Authorization Option 1</category></item></channel></rss>